Translate WordPress Websites Globally with ConveyThis Translate [conveythis-translate] <= 269.5 (unfixed)
unknown
[en] Missing Authorization vulnerability in ConveyThis ConveyThis conveythis-translate allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ConveyThis: from n/a through <= 269.5.
- Affected:
- up to 269.5
- Fix:
- No patched version reported
- Disclosed:
- Feb 20, 2026
CVE-2025-68021 on NVD →
ConveyThis <= 270.4 - Missing Authorization
medium
The ConveyThis plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 270.4. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 270.4
- Fixed in:
- 270.5
- Disclosed:
- Jan 27, 2026
CVE-2025-68021 on NVD →
Translate WordPress Websites Globally with ConveyThis Translate [conveythis-translate] <= 268.10 (unfixed)
unknown
[en] Missing Authorization vulnerability in ConveyThis ConveyThis conveythis-translate allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ConveyThis: from n/a through <= 268.10.
- Affected:
- up to 268.10
- Fix:
- No patched version reported
- Disclosed:
- Dec 9, 2025
CVE-2025-62152 on NVD →
ConveyThis <= 269.2 - Missing Authorization
medium
The ConveyThis plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 269.2. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 269.2
- Fixed in:
- 269.3
- Disclosed:
- Nov 29, 2025
CVE-2025-62152 on NVD →
Language Translate Widget for WordPress – ConveyThis <= 269.1 - Authenticated (Administrator+) PHP Object Injection
medium
The Language Translate Widget for WordPress – ConveyThis plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 269.1 via deserialization of untrusted input. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No kn...
- CVSS:
- 6.6
- Affected:
- up to 269.1
- Fixed in:
- 269.2
- Disclosed:
- Sep 22, 2025
CVE-2025-57919 on NVD →
Translate WordPress Websites Globally with ConveyThis Translate [conveythis-translate] < 235
unknown
[en] Missing Authorization vulnerability in ConveyThis Translate Team Language Translate Widget for WordPress – ConveyThis allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Language Translate Widget for WordPress – ConveyThis: from n/a through 234.
- Affected:
- up to 235
- Fixed in:
- 235
- Disclosed:
- Nov 1, 2024
CVE-2024-38792 on NVD →
Language Translate Widget for WordPress – ConveyThis <= 234 - Missing Authorization to Limited Option Update
medium
The Language Translate Widget for WordPress – ConveyThis plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the /app/connect/ConveyThisStart.php file in versions up to, and including, 234. This makes it possible for unauthenticated attackers to update the api_ke...
- CVSS:
- 5.3
- Affected:
- up to 234
- Fixed in:
- 235
- Disclosed:
- Jul 22, 2024
CVE-2024-38792 on NVD →
Translate WordPress Websites Globally with ConveyThis Translate [conveythis-translate] < 224
unknown
[en] The Language Translate Widget for WordPress – ConveyThis plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'api_key’ parameter in all versions up to, and including, 223 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject...
- Affected:
- up to 224
- Fixed in:
- 224
- Disclosed:
- Apr 11, 2024
CVE-2023-6811 on NVD →
Language Translate Widget for WordPress – ConveyThis <= 223 - Unauthenticated Stored Cross-Site Scripting via api_key
high
The Language Translate Widget for WordPress – ConveyThis plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'api_key’ parameter in all versions up to, and including, 223 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbi...
- CVSS:
- 7.2
- Affected:
- up to 223
- Fixed in:
- 224
- Disclosed:
- Apr 10, 2024
CVE-2023-6811 on NVD →
Translate WordPress Websites Globally with ConveyThis Translate [conveythis-translate] <= 266 (unfixed)
unknown
- Affected:
- up to 266
- Fix:
- No patched version reported
CVE-2025-57919 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database